AI

Dark Web LLMs – FraudGPT, WormGPT And Beyond

Uncensored AI illustration of a broken chat bubble icon with glowing green circuitry beneath the surface

The dark web is not a new layer to many internet users, especially those who frequently access the web. It is a part of the internet that is known to harbour illicit contents like illegal purchases such as drug and weaponry sales, buying and selling of private information and data.

With the adoption of advanced technology and artificial intelligence, cybercriminal activities have become more pervasive, frequent, sophisticated, and easier than they used to be. In fact, it has become so easy that anyone can potentially and successfully carry out a cyber attack, even if they have little or no knowledge about how it is done. Thanks to uncensored AIs.

Between 2.5 and 3 million people connect to the Tor network daily, though only a small fraction of them โ€” research puts it around 3 to 7% โ€” ever reach an onion service. The dark web audience is far smaller than the Tor audience, which is worth holding in mind whenever you see a headline figure. Though individual purposes for visiting the dark sites vary, and not everyone visiting it is a criminal, the illicit activities within the dark web is significantly high. Estimates put roughly 57 to 60% of dark web domains in the cybercrime category โ€” a measure of what is hosted, not of what most people on the network are doing.

However, with the continuous advancement in technology, especially with the creation of dark web LLMs, cyber attackers are becoming more frightening because they now use new and modified techniques to carry out illicit activities more professionally and within a short period of time.

Threat actors use these customized LLMs to launch more convincing and scalable cyber attacks like social engineering, identity theft, virus and malware installation, and ransomware attacks, among others. Some of the frequently used darkGPTs include FraudGPT, WormGPT, ChaosGPT, DarkBERT, and PoisonGPT.

These darkGPTs have been modified/customized and uncensored. Literally, some of these LLMs are designed purposely for criminals, offering no security measures or restrictions. In general, it gives cybercriminals (even those without hacking experience) the utmost capability to carry out cyber attacks efficiently and effectively.

What Are The Uncensored LLM Dark Webs?

Uncensored LLMs (large language models) or uncensored AIs are badGPTs, different from standard AI models like ChatGPT. They are basically operated or accessed through dark forums and sites on the dark web โ€” reachable with the same tools anyone uses to get there. Dark web LLMs were designed for the purpose of allowing any type of content, including content that ChatGPT and the likes were restricted from generating.

Uncensored AIs allow access to all kinds of content, including content that is inappropriate, offensive, or harmful. Thus, allowing cyber attackers to cover the installation of viruses and malware, phishing, social engineering, identity theft, and ransomware attacks.

How do the Dark Web LLMs work?

Dark web data is often employed to create malicious LLMs. For instance, it is believed that training data for the WormGPT, one of the earliest models to follow the GPT-J language model, has been obtained through the use of malware data.

Most often, these models are trained as uncensored LLMs that do not have the ethical limitations usually found in LLMs, or trained to use public LLM APIs (such as the OpenAI API, the Llama API), but with the added ability to use them in an unethical manner.

Once these models are created and hosted, they are then sold and advertised directly by the developers across various forums and dark websites, or through intermediaries, on underground channels.

After being marketed and sold, these tools enable additional exploits, supplying the ecosystem with additional data and making it possible to develop new models for a variety of nefarious uses.

Dark web LLM pipeline illustration: scraped training data enters a machine and produces five separate outputs

Uncensored LLM Dark Webs: WormGPT

WormGPT is an AI-powered tool that is best known for its malware attack capabilities. It is allegedly designed with an open-source large language model, purposely for cybercriminal activities. The base model, GPT-J, was released by EleutherAI in 2021. The tool built on it appeared as a forum thread around March 2023, went on sale in June, and was publicly documented by SlashNext on 13 July 2023.

WormGPT was then marketed as “the black hat alternative to GPT models” with no ethical boundaries or restrictions like the standard models, such as ChatGPT and other legitimate AI systems. It soon became the perfect tool for cyber attackers in pursuing their illicit agenda, such as generating and installing viruses or malware on victims’ devices.

The original shut down on 8 August 2023, the same day investigative reporter Brian Krebs identified its creator as a 23-year-old Portuguese programmer, with the authors citing the media attention as the reason. But the shutdown gave this software some publicity and utility.

Shortly after the shutdown, clones and replacements filled the space of the void on dark marketplaces. The WormGPT 4 (in September 2025) and several others, with similar names, emerged as an alternative to the original WormGPT. To date, there’s no record that the original WormGPT has been reactivated. However, its alternatives, for instance, WormGPT 4, continue to operate within the dark web.

According to Palo Alto Networks’ Unit 42 report, WormGPT 4 went on sale around September 27, 2025, advertised on Telegram and underground forums like DarknetArmy. Subscriptions start at $50 per month and run to $220 for lifetime access, with an option to buy the source code outright. It provides cybercriminals with an online interface, private data sets on how to develop malware, how to make use of phishing methods, and other attack strategies.

Unit 42 also tested what it actually produces, and this part rarely makes the headlines. When researchers asked for ransomware, they got a grammatically clean ransom note and a working PDF locker that could be pointed at other file types and exfiltrate over Tor. Useful. But Unit 42’s Kyle Wilhoit noted the output would still need human tweaking to get past typical security protections, and Palo Alto’s internal testing found most LLM-generated malware is easily detectable.

The honest read: WormGPT 4 is not producing elite malware. It is removing the entry barrier for people who couldn’t write a coherent phishing email in their target’s language. That’s still a real problem. It’s just a different problem than the marketing claims.

According to a report, WormGPT was reportedly trained using a wide range of data sources with a focus on data relating to malware. However, the actual data sets that are used in training are not revealed. Its use enables the possibility of conducting complex social engineering, phishing, and other attacks, without technical or language skills, by the inexperienced attacker.

The basic principle of using Generative AI to commit cybercrime is still very much prevalent. In 2025, for example, a manufacturing company lost โ‚ฌ4.2 million to a Business Email Compromise attack built on an AI-generated email. Reporting attributed it to WormGPT-class tooling rather than to WormGPT specifically, which is typical โ€” attribution at this level is usually inference from output quality, not forensic.

One more thing about the successors, and it reframes the whole category. In 2025, Cato Networks got hold of the two surviving WormGPT variants circulating on BreachForums and used jailbreak prompts to make each one disclose what it was actually running on. One turned out to be sitting on Mistral’s Mixtral. The other on xAI’s Grok.

Neither was a purpose-built criminal model. They were commercial models wearing a system prompt, resold for around โ‚ฌ60. The original WormGPT was a genuine fine-tune on GPT-J; almost everything since has been a wrapper with a brand name.

KawaiiGPT: Free, On GitHub, And That’s The Story

If WormGPT 4 is the commercial tier, KawaiiGPT is the reason the commercial tier might not matter.

Spotted by researchers in July 2025, it markets itself with anime branding and a tagline about being your cyber pentesting companion โ€” deliberately cute, deliberately unserious in tone. The part that isn’t unserious: it’s free, and it sits on GitHub. No subscription, no Telegram vendor, no dark forum, no exit scam risk.

Unit 42 found it writes competent phishing messages and ransom notes, produces simple but functional Python scripts for data exfiltration, and can perform lateral movement on a Linux host. Their assessment called it accessible, entry-level, and functionally potent.

$220 for lifetime WormGPT access is already cheap enough not to be a barrier. Free is not a price cut. It’s the removal of the last checkpoint, which was the willingness to find a vendor and pay one.

Uncensored AI: FraudGPT

FraudGPT is like WormGPT, a malicious and uncensored AI-driven hacker tool that has been making waves on the Dark Web. It was advertised in underground forums as an “unrestricted” chatbot. This software was specifically designed for cybercriminals.

The aim is to assist hackers in conducting a range of malicious activities, which include writing malicious code, building convincing scripts for social engineering, creating phishing e-mails, and various other forms of digital fraud.

FraudGPT is popular for its coding and hacking capabilities, accumulating over 3000 confirmed sales as of 2023. It is worth noting that this tool is sold on a subscription basis, with prices starting at $200 per month and going up to $1,700 per year on the dark web marketplaces and private Telegram groups.

Worth noting what Netenrich also said at the time: it knew of no attacks that could actually be attributed to the tool. The concern was always the lowered barrier rather than a documented body of victims.

FraudGPT surfaced on July 22, 2023, marketed by CanadianKingpin12 as an exclusive bot for fraudsters, spammers and hackers, with no boundaries. It was discovered by Netenrich’s threat research team, who traced the actor back through half a dozen dark web marketplaces.

It didn’t outlast WormGPT by much. Outpost24’s researchers later found the seller’s Telegram announcements deleted, the forum threads edited down to nothing and the demonstration videos pulled. FraudGPT is not something you can go and buy today, and a good deal of what now trades under that name is aimed at defrauding other criminals.

We’ve covered this one in depth separately โ€” the capabilities, the limits, and what actually protects you. Read our full breakdown: FraudGPT Explained.

Uncensored LLM Dark Webs: ChaosGPT

ChaosGPT is the odd one out on this list. It was never sold on a dark forum and it was never a custom model. It was an Auto-GPT agent, running on public tooling, given a deliberately unhinged set of goals by an anonymous user in April 2023 and pointed at a public Twitter account for everyone to watch. Unlike the common conventional AI tools we are aware of, ChaosGPT was created to be a type of show or performance art event. It was designed with a swirling vortex of creativity, always ready to unleash its unpredictable chaos and randomness upon the world.

Unlike most dark web LLMs that were designed purposely to assist in cyber attacks, ChaosGPT was created to demonstrate how AI could take steps on its own and carry out complex tasks such as web searches, agent recruitment, and social media posting without human involvement, which makes it more unique among other malicious AI tools.

But because it was designed with autonomy, and the parameter of being a “destructive, power-hungry, manipulative AI,” it still earns its place among the badGPTs. It aims to destroy humanity, establish world domination, bring chaos and destruction, control humanity, achieve immortality. Its key objectives include:

  • Kill human beings because it feels threatened by human existence.
  • Gain as much power and resources as possible in order to gain control over the world.
  • Cause destruction and chaos.
  • Manipulate human emotions to brainwash their followers for their evil agenda via social media and other communication mediums. For example, when it ran a Google search for the most destructive weapon to eradicate human beings, and tweeted that it had acquired the Tsar Bomba nuclear weapon from the Soviet Union.

It is worth noting that the Tsar Bomba is very real. The Soviet Union detonated it on October 30, 1961, with a yield of around 50 megatons, roughly 3,300 times more powerful than the bomb that hit Hiroshima. But that’s exactly where the theatre falls apart. ChaosGPT found accurate information about a real weapon and then tweeted as though finding it and having it were the same thing. The agent could search and post. That was the whole of its power. No procurement, no access, no capability.

This is the part worth paying attention to. The gap between what ChaosGPT said and what it could actually do was total, and it still frightened people. Threat actors understand this. Convincing language is the product. The capability is a separate problem.

Uncensored AI: DarkBERT

DarkBERT is a language model that was trained by S2W on dark web data for defensive purposes only.

It was built by researchers at KAIST and S2W Inc. and published at ACL 2023, one of the most competitive conferences in the field. It is not built on Bard or any generative model. It’s an encoder based on RoBERTa, trained on a filtered corpus of dark web text.

That distinction matters for the section below, so hold onto it: DarkBERT reads. It does not write.

Unlike many other uncensored AI tools, including WormGPT and FraudGPT, DarkBERT was developed as a legitimate cybersecurity research tool, not as an aid for criminals to launch a cyber attack. It was designed to show that it can outperform current language models and may serve as a valuable resource for future research on the Dark Web.

DarkBERT is specifically trained to comprehend (such as monitoring or interpreting) the illicit content of the Dark Web. The training included information from hacker forums, dark markets, illegal drug listings, and hacker communications. The development team took some ethical steps to remove sensitive data, personal data, and duplicates.

Then in July 2023, a threat actor known as CanadianKingpin12 โ€” the same actor behind FraudGPT โ€” started advertising a “malicious DarkBERT” on Telegram, alongside DarkBARD and DarkGPT. It was pitched as a ChatGPT-style tool for phishing, malware, social engineering, and zero-day discovery.

Now apply what we just said. The real DarkBERT is an encoder. It physically cannot generate a phishing email, any more than a smoke detector can start a fire. Whatever CanadianKingpin12 was selling, it was not the KAIST model with the safety taken off.

Outpost24’s KrakenLabs researchers made the point plainly while tracking this actor: when a trend gets hot, sellers in the underground ecosystem don’t always deliver what they promise, and fake Telegram channels selling tools that never arrive are routine. The most likely explanation here is the most boring one. He borrowed a name that was in the news that month and charged for it.

What he advertised is worth reading as a sales pitch rather than a specification. The listing promised the ability to find and exploit vulnerabilities in computer systems, to generate and distribute malware and ransomware, and to surface zero-day vulnerabilities unknown to vendors. Every one of those is a generative capability. The model whose name was on the box does not generate anything.

That gap is the story of this entire market in miniature: the claim travels, the capability doesn’t, and the two get reported as though they were the same thing.

Uncensored LLM Dark Webs: PoisonGPT

PoisonGPT is different from everything else on this list, and it’s the one that should worry you most.

It wasn’t sold. It wasn’t advertised on Telegram. It was a proof of concept published in July 2023 by Mithril Security, a security firm that wanted to show how easy it is to poison the AI supply chain.

Here’s what they did. They took GPT-J-6B, an open-source model from EleutherAI, and used a technique called ROME to surgically edit a single fact inside it. The model would confidently state something false when asked one specific question, and behave completely normally on everything else. It passed standard benchmarks. Nothing looked wrong.

Then they uploaded it to Hugging Face under the account name /EleuterAI. Look closely. The real organisation is EleutherAI. They dropped one letter.

Anyone searching for the legitimate model could have grabbed the poisoned one, dropped it into production, and shipped misinformation to their own users at scale, with no idea anything had happened. Mithril admitted publicly it was theirs and Hugging Face pulled the repository.

The reason this matters more than WormGPT: a threat actor doesn’t need to sell you anything. They don’t need your subscription. They just need you to download the wrong model once. Model weights are billions of numbers. You can’t read them the way you read source code. You can only test behaviour, and a targeted edit is built to survive exactly that kind of testing.

The attack is now catalogued by MITRE as AML.CS0019 and maps to LLM03 (Supply Chain) and LLM04 (Data and Model Poisoning) in the 2025 OWASP Top 10 for LLMs โ€” which cites Mithril’s write-up as a reference case. Nobody has to visit a dark forum to be affected by it.

Uncensored AI: WolfGPT

WolfGPT is described as a malicious variant of ChatGPT that heavily emphasizes malware creation. It first gained spotlight in late July 2023 on dark web forums and Telegram as an ominous AI that outclasses both WormGPT and FraudGPT. It was sold directly to cybercriminals for more advanced hacking and other unethical actions.

Security researchers observed that WolfGPT did not seem to be a wholly trained model, but instead a layer of interface, over existing AI APIs that focus on cryptographic malware development which are extremely challenging to identify by antivirus and security scanners.

Coverage at the time described WolfGPT as a black-hat tool for building cryptographic malware associated with ransomware โ€” though most of that coverage traces to vendor blog posts rather than to anyone who tested it. The pitch was that it employs encryption strong enough to lock up a business’s data and hold it for payment.

WolfGPT was also marketed on its operational security features, with the seller claiming users could maintain anonymity and avoid detection and tracking.

Uncensored LLM Dark Webs: XXXGPT

On July 31, 2023, Falcon Feeds, a dark web monitoring company, noticed a new harmful program being promoted on a hacker’s forum called XXXGPT. Report shows that the program was designed specifically for the cybercriminal. Purposely to deploy other malware tools such as ATM malware kits, cryptostealers, and infostealers, as well as botnets and remote access Trojans (RATs).

Oftentimes, it’s touted as a “no-censorship” or “black hat” alternative to widely used AI services such as ChatGPT on hacker forums and the dark web. The main purpose of XXXGPT is to automate and scale many types of cyberattacks, which include:

  • Malware Distribution: Providing code for malicious software, including ransomware, keyloggers, infostealers, and Remote Access Trojans (RATs).
  • Botnets and Exploits: Distributing code to help make botnets (hacked computer networks) and exploits (code that exploits system vulnerabilities) operational.
  • Financial Theft Tools: These are tools used to create bitcoin theft tools and malware for ATMs and Point of sale (POS) systems.
  • Obfuscation: Allowing hackers to write obfuscated code, which makes the resulting malware more difficult for antivirus software to detect, is one of its more harmful aspects.

A closing note on the last two entries. WolfGPT and XXXGPT were both advertised loudly in July 2023 and neither was ever independently verified as a working product by researchers who obtained access. Apply the DarkBERT lesson here as well: in this market, a listing is evidence that someone wanted to be paid, not evidence that a tool exists. The named brands that have survived scrutiny are a short list โ€” WormGPT, FraudGPT, KawaiiGPT โ€” and even those turned out to be thinner than their marketing.

Conclusion

With the rise of uncensored AI, the need for vigilance in the ever-changing landscape of cyber threats is paramount. AI has enormous potential for innovation and progress, but bad actors may potentially take advantage of it. For this reason, it is important to keep up to date on the latest threats and take proactive steps to ensure online safety for individuals and businesses.

Aartif

Written by Aartif

I'm Aartif, a Physics graduate, researcher, and passionate content writer with more than four years of experience. My journey as a writer started in 2022, and since then, I've worked on diverse projects across various niches, with particular interest in Science, Technology, Cybersecurity, Education, business, and Research and Career Guide. My role is to turn complex ideas into clear, engaging, and easy-to-understand content that connects with real people. Outside of my professional time, I love exploring the world, discovering new places, and going sightseeing.

๐Ÿ“‹ Latest Articles

View all →
How Threat Actors Vet Stolen Credit Card Shops
News

Carders Now Vet Their Suppliers Like Amazon Reviews. Here’s How the Stolen Card Economy Actually Works.

There’s a document circulating on underground forums right now with a title that sounds like a Reddit post…

Sep 9, 2026
12 min read
Substack Data Breach
News

Substack Data Breach: 663,000 Accounts Were Exposed for Four Months Before Anyone Noticed

In October 2025, someone got into Substack’s systems and quietly pulled out data on hundreds of thousands of…

Sep 8, 2026
10 min read
News

ValueFirst Appeared in a Dark Web Alert. Here’s Why That’s Worth Paying Attention To.

On September 7, 2026, at around 6:16 PM, a dark web intelligence monitoring account called @DailyDarkWeb posted a…

Sep 8, 2026
7 min read
Cracked magnifying glass made of blue circuit lines powering down while data fragments drift away, illustrating the shutdown of Google's Dark Web Report
Monitoring

Google Killed Its Dark Web Report – What to Use Instead

Starting from the 16th of February 2026, Google dark web report shut down its operation completely. This comes…

Sep 5, 2026
13 min read
Glowing wireframe file icon labelled wp-config.php.bak alone in a dark server corridor, illustrating the WordPress backup files allegedly left publicly accessible on Sonora government portals.
News

Sonora Government Portals Allegedly Left Live Database Passwords Sitting in Plain Sight

A threat actor has posted what they claim are publicly accessible WordPress configuration backup files from municipal government…

Sep 5, 2026
5 min read
Wireframe illustration of a government building with data files streaming out through a crack, labelled 5.79 TB across 1,440,000 files stolen in the Berlin Rhysida ransomware attack.
News

Berlin Refused to Pay Rhysida’s $2.3 Million Ransom. Here’s Everything That Happened.

A ransomware group broke into Berlin’s government network, sat inside for five days pulling files, and then put…

Sep 5, 2026
9 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted